Data Privacy
AMT structures its data-processing practices around China’s Data Security Law, PIPL and cross-border transfer rules, with mapping to key GDPR requirements, DPA templates and support for data-subject rights.
- China laws
- DSL / PIPL / cross-border rules
- Intl mapping
- GDPR (DPO / DPA / rights)
- Rights
- All 7 data-subject rights
- Deletion
- 30 / 90 / 180 days post-termination
China data-law compliance
AMT’s data-processing activities are designed around China’s three pillar data-protection laws.
Data Security Law
Data classification, important-data identification and lifecycle security management.
PIPL
Lawful processing bases, informed consent and separate consent for sensitive data.
Cross-border assessment rules
Transfer-route selection, standard-contract filing and PIPIA.
GDPR alignment
For customers with cross-border operations, AMT maps its privacy controls to key GDPR concepts for legal and procurement review.
- Six lawful bases
Consent / contract / legal obligation / vital interests / public interest / legitimate interests.
- Data Processing Agreement
A standard DPA template setting out controller / processor duties and sub-processor terms.
- Data Protection Officer
A data-protection contact is reachable at privacy@amt.com.cn.
- Data-subject rights
Supports access, rectification, erasure, restriction, portability and objection (GDPR Arts. 15–22).
AMT privacy practices
- Data minimisation
We collect only what the service requires, avoiding over-collection.
- Purpose limitation
Data is used only for agreed purposes; new purposes require fresh consent.
- Encryption
Encryption at rest and in transit, with extra protection for sensitive fields.
- Access control + audit logs
Least-privilege access with auditable logging of key actions.
- Deletion options
After termination, customers can choose a 30 / 90 / 180-day deletion window.
- Portability & export
Structured-format export to support migration and backup.
Supporting data-subject rights
AMT supports the following seven data-subject rights and helps customers, as controllers, respond to their end users.
Right to be informed
Clear notice of how data is collected and used.
Right of access
Access to how personal data is processed.
Rectification
Correct inaccurate personal data.
Erasure
Request deletion where applicable.
Restriction
Request a pause on certain processing.
Portability
Obtain or move data in a structured format.
Objection
Object to legitimate-interest processing.
Data Processing Agreement (DPA)
Customers can request a standard DPA template that sets out each party’s role and obligations.
AMT offers a standard DPA template aligned with both PIPL and GDPR frameworks, covering processing scope, purpose, duration, categories of data subjects, security measures (including ISO 27001 controls), sub-processor management, breach notification, deletion and return of data, and audit rights.
- Request the latest DPA template via the sales or legal workflow.
- See the Sub-processors page for the current list.

